I dunno; if an open source project wants to take public sector funding, then some kinds of public sector oversight (e.g. public sector requiring security audits, or SBOMs, etc which they pay for) could be very desirable indeed.
If your implication is that the government who's funding it might then try to leverage the project somehow (e.g. insert a backdoor or whatever), then we're back with the original problem of needing to protect FOSS projects from malicious actors wherever they come from.
I'd argue that the benefits of actually being funded massively outweigh the risks of the funder going rogue, given you can use the funding to build checks & balances to protect against malicious activity no matter the source.